ExamGecko
Question list
Search
Search

Question 51 - IT Risk Fundamentals discussion

Report
Export

To address concerns of increased online skimming attacks, an enterprise is training the software development team on secure software development practices. This is an example of which of the following risk response strategies?

A.

Risk acceptance

Answers
A.

Risk acceptance

B.

Risk avoidance

Answers
B.

Risk avoidance

C.

Risk mitigation

Answers
C.

Risk mitigation

Suggested answer: C

Explanation:

The enterprise is addressing concerns about increased online skimming attacks by training the software development team on secure software development practices. This is an example of risk mitigation because it involves taking steps to reduce the likelihood or impact of the risk.

Risk Response Strategies Overview:

Risk Acceptance: Choosing to accept the risk without taking any action.

Risk Avoidance: Taking action to completely avoid the risk.

Risk Mitigation: Implementing measures to reduce the likelihood or impact of the risk.

Risk Transfer: Shifting the risk to another party (e.g., through insurance).

Explanation of Risk Mitigation:

Risk mitigation involves implementing controls and measures that will lessen the risk's likelihood or impact.

Training the software development team on secure software development practices directly addresses the potential vulnerabilities that could be exploited in online skimming attacks, thereby reducing the risk.

ISA 315 (Revised 2019), Anlage 6 discusses the importance of understanding and implementing IT controls to mitigate risks associated with IT systems.

asked 18/11/2024
Said Jabri
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first